EIP-2026-113498
PRE-CVEWordPress Core 2.2 - 'wp-app.php' Arbitrary File Upload
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113498. PoCs published by Alexander Concha.
AI-analyzed exploit summary This Perl script exploits an arbitrary file upload vulnerability in WordPress 2.2 and WordPress MU <= 1.2.2 by leveraging authenticated user privileges to upload a file via a PUT request to a vulnerable endpoint. It automates authentication, post creation, and file upload to achieve remote code execution.
Description
WordPress Core 2.2 - 'wp-app.php' Arbitrary File Upload
Exploits (1)
This Perl script exploits an arbitrary file upload vulnerability in WordPress 2.2 and WordPress MU <= 1.2.2 by leveraging authenticated user privileges to upload a file via a PUT request to a vulnerable endpoint. It automates authentication, post creation, and file upload to achieve remote code execution.